Deleting A Security Association; Security Association Notes - NETGEAR FR314 Reference Manual

Cable/dsl firewall and vpn routers
Hide thumbs Also See for FR314:
Table of Contents

Advertisement

Reference Guide for the Model FR314, FR318 and FV318 Cable/DSL Firewall and VPN Routers
The Shared Secret must be between 8 and 128 characters. For greater security, enter a
combination of letters, numbers and symbols, such as "Aa8^Hjj@e$FF#." Letters are case
sensitive.
Destination Network Address: Enter the network IP address and subnet mask for the remote
7.
network to which your VPN will connect.
The two endpoint networks must have different LAN IP address ranges. For example, if both
ends are using the Netgear default address range of 192.168.0.x, the connection will not work.
Change one router's LAN IP Address and DHCP range to a different range such as
192.168.1.x.
If the remote endpoint is a VPN PC client, its destination address must be a single IP address,
with a subnet mask of 255.255.255.255. If its address is dynamically-assigned (or assigned by
DHCP), Netgear recommends that you enter a "virtual fixed" IP address in the range of
172.16.0.x, with a subnet mask of 255.255.255.255, and enter this address in the configuration
of the VPN client software. If you are creating multiple VPN client SAs (FV318 only), select a
different "virtual fixed" IP address for each SA.

Deleting a Security Association

To delete a security association:
Go to the VPN Configure window.
1.
In the Security Association drop-down box, select the security association to be deleted.
2.
Click on the Delete This SA button.
3.
Click on the Update button.
4.

Security Association Notes

Internet Key Exchange (IKE) with pre-shared secrets will be used.
VPN Client connnections will use HMAC MD5 auhentication
SA Life Time is 8 Hours.
A finite SA Life Time increases security by forcing the two VPN endpoints to update the
encryption and authentication keys. However, every time the VPN tunnel renegotiates, users
accessing remote resources are disconnected.
For increased reliability, Keep Alive will always be enabled for router to router SA's (Peer
Netgear Router)
Virtual Private Networking
10-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fr318Fv318

Table of Contents